๐จ TP-Linkโs Omada gateways just got hit with four major security flaws โ two can let hackers run commands without logging in.
A remote attacker could take full control โ no password needed.
Patch now. Details โ https://thehackernews.com/2025/10/tp-link-patches-four-omada-gateway.html
A remote attacker could take full control โ no password needed.
Patch now. Details โ https://thehackernews.com/2025/10/tp-link-patches-four-omada-gateway.html
๐15๐คฏ6๐ฅ1
A tiny Rust bug just broke thousands of builds.
Itโs called TARmageddon (CVE-2025-62518) โ a flaw in the async-tar library that lets attackers slip hidden files inside nested TAR archives.
Unpatched since 2023, developers are now racing to fix it โ https://thehackernews.com/2025/10/tarmageddon-flaw-in-async-tar-rust.html
Itโs called TARmageddon (CVE-2025-62518) โ a flaw in the async-tar library that lets attackers slip hidden files inside nested TAR archives.
Unpatched since 2023, developers are now racing to fix it โ https://thehackernews.com/2025/10/tarmageddon-flaw-in-async-tar-rust.html
๐16๐ฅ1๐ค1
๐จ PassiveNeuron is still active.
Hackers are breaking in through Microsoft SQL servers, planting custom malware (Neursite & NeuralExecutor), and even using GitHub to hide their command servers โ a rare move in state-level spying.
Full story โ https://thehackernews.com/2025/10/researchers-identify-passiveneuron-apt.html
Hackers are breaking in through Microsoft SQL servers, planting custom malware (Neursite & NeuralExecutor), and even using GitHub to hide their command servers โ a rare move in state-level spying.
Full story โ https://thehackernews.com/2025/10/researchers-identify-passiveneuron-apt.html
๐ฅ14๐3
๐ค Nearly 40% of alerts still go unseen.
AI-SOCs now handle triage, cut false positives, and alert teams with full context. But as Shahar Ben-Hador explains โ outsource or not, you still own the breach.
$30K vs $100K+โฆ hereโs who should switch โ https://thehackernews.com/expert-insights/2025/10/what-happens-to-mssps-and-mdrs-in-age.html
AI-SOCs now handle triage, cut false positives, and alert teams with full context. But as Shahar Ben-Hador explains โ outsource or not, you still own the breach.
$30K vs $100K+โฆ hereโs who should switch โ https://thehackernews.com/expert-insights/2025/10/what-happens-to-mssps-and-mdrs-in-age.html
๐4๐ฅ2๐ค1
๐ 8-character passwords are dead.
๐ Hackers crack โP@ssw0rd!โ in months.
๐ก The fix isnโt symbols โ itโs length.
16 simple letters beat any complex mix.
Use words, not symbols.
Why your policy still fails โ https://thehackernews.com/2025/10/why-you-should-swap-passwords-for.html
๐ Hackers crack โP@ssw0rd!โ in months.
๐ก The fix isnโt symbols โ itโs length.
16 simple letters beat any complex mix.
Use words, not symbols.
Why your policy still fails โ https://thehackernews.com/2025/10/why-you-should-swap-passwords-for.html
๐ฅ22๐8๐ค3
Hackers linked to China exploited a โpatchedโ Microsoft SharePoint flaw to break into networks across four continents.
It wasnโt just spying โ they found a way to bypass the patch that fixed a previous bypass.
Symantec warns the campaign is still spreading.
Read โ https://thehackernews.com/2025/10/chinese-threat-actors-exploit-toolshell.html
It wasnโt just spying โ they found a way to bypass the patch that fixed a previous bypass.
Symantec warns the campaign is still spreading.
Read โ https://thehackernews.com/2025/10/chinese-threat-actors-exploit-toolshell.html
๐คฏ17๐ฅ8๐1
Your cloud might flag the same issue across five tools โ XDR, CSPM, SIEM, CMDB, and more.
Each reports it differently. None resolve it.
Thatโs the real challenge: detection is easy; remediation isnโt.
Learn how Pentera Resolve turns alerts into action โ https://thehackernews.com/2025/10/bridging-remediation-gap-introducing.html
Each reports it differently. None resolve it.
Thatโs the real challenge: detection is easy; remediation isnโt.
Learn how Pentera Resolve turns alerts into action โ https://thehackernews.com/2025/10/bridging-remediation-gap-introducing.html
๐5๐ฅ1
Which Industries Are Most at Risk for DDoS Attacks?
While DDoS attacks can hit any organization, some industries face far higher riskโand potentially greater impact when they do.
The latest DDoS Resiliency Score (DRS) report ranks the industries most frequently targeted and explains why.
Here's the list of the highest risk sectors. For the full list of industries, see here - https://thn.news/ddos-risk-map
Highest-risk sectors:
๐ฐ Financial Services โ Targets of hacktivism and extortion-driven outages.
โก Energy โ At risk from politically or state-backed disruptions.
๐๏ธ Government โ Frequent hacktivist targets, especially around elections.
๐ Telecom โ Increasingly hit by ransom-based attacks.
๐ฎ Gaming & Gambling โ Vulnerable to extortion and competitive disruption.
๐ป SaaS & Software โ Susceptible to DDoS that erodes customer trust.
While DDoS attacks can hit any organization, some industries face far higher riskโand potentially greater impact when they do.
The latest DDoS Resiliency Score (DRS) report ranks the industries most frequently targeted and explains why.
Here's the list of the highest risk sectors. For the full list of industries, see here - https://thn.news/ddos-risk-map
Highest-risk sectors:
๐ฐ Financial Services โ Targets of hacktivism and extortion-driven outages.
โก Energy โ At risk from politically or state-backed disruptions.
๐๏ธ Government โ Frequent hacktivist targets, especially around elections.
๐ Telecom โ Increasingly hit by ransom-based attacks.
๐ฎ Gaming & Gambling โ Vulnerable to extortion and competitive disruption.
๐ป SaaS & Software โ Susceptible to DDoS that erodes customer trust.
๐ฅ11โก4
๐จ Developers, check your NuGet packages.
A fake NuGet package โNetherะตum.Allโ โ spelled with a Cyrillic โeโ โ was stealing wallet keys from Ethereum .NET projects.
It even faked 11.7M downloads to look real.
Full story โ https://thehackernews.com/2025/10/fake-nethereum-nuget-package-used.html
A fake NuGet package โNetherะตum.Allโ โ spelled with a Cyrillic โeโ โ was stealing wallet keys from Ethereum .NET projects.
It even faked 11.7M downloads to look real.
Full story โ https://thehackernews.com/2025/10/fake-nethereum-nuget-package-used.html
๐คฏ9โก2๐ฅ2๐1
๐ด A fake โZoom meetingโ from Ukraineโs Presidentโs Office just hacked aid workers. The CAPTCHA wasnโt real โ it opened a live remote shell through WebSocket.
A one-day domain. Six months of setup. Russian servers behind it.
The trojanโs still active โ https://thehackernews.com/2025/10/ukraine-aid-groups-targeted-through.html
A one-day domain. Six months of setup. Russian servers behind it.
The trojanโs still active โ https://thehackernews.com/2025/10/ukraine-aid-groups-targeted-through.html
๐คฏ19๐7๐ฅ6
โ ๏ธ An Iranian hacking group used a real email account to plant a new backdoor in 100+ Middle East government networks.
They sent it through real diplomatic inboxes โ and it worked.
Read โ https://thehackernews.com/2025/10/iran-linked-muddywater-targets-100.html
They sent it through real diplomatic inboxes โ and it worked.
Read โ https://thehackernews.com/2025/10/iran-linked-muddywater-targets-100.html
๐ฅ26๐คฏ10๐ฑ6โก3๐2๐1
๐จ CISA just warned about a critical bug in Motex Lanscope (CVE-2025-61932).
Hackers can take control of systems by sending one malicious packet.
Itโs already being used in real attacks.
Fix it before Nov 12 โ https://thehackernews.com/2025/10/critical-lanscope-endpoint-manager-bug.html
Hackers can take control of systems by sending one malicious packet.
Itโs already being used in real attacks.
Fix it before Nov 12 โ https://thehackernews.com/2025/10/critical-lanscope-endpoint-manager-bug.html
๐ฅ5
๐จ New Adobe Commerce flaw (CVE-2025-54236, CVSS 9.1) under active attack.
Over 250 exploit attempts in 24 hoursโmostly on unpatched Magento sites.
PoC is public. Patch now.
Details โ https://thehackernews.com/2025/10/over-250-magento-stores-hit-overnight.html
Over 250 exploit attempts in 24 hoursโmostly on unpatched Magento sites.
PoC is public. Patch now.
Details โ https://thehackernews.com/2025/10/over-250-magento-stores-hit-overnight.html
๐ฅ5
๐ Hackers found a new jackpot โ cloud gift cards.
A group called Jingle Thief broke into retail cloud systems and quietly issued fake gift cards for months, hiding inside Microsoft 365 accounts.
Full story โ https://thehackernews.com/2025/10/jingle-thief-hackers-exploit-cloud.html
A group called Jingle Thief broke into retail cloud systems and quietly issued fake gift cards for months, hiding inside Microsoft 365 accounts.
Full story โ https://thehackernews.com/2025/10/jingle-thief-hackers-exploit-cloud.html
๐24๐คฏ4๐ฑ1
In this 20-minute session, learn how to harden your images, secure dependencies, and lock down your CI/CD pipeline against real-world supply chain attacks.
๐ Tuesday, Oct 28 | 8 AM PST | 11 AM EST
๐ฅ Register Now โ https://thn.news/secure-stack-webinar
๐ Tuesday, Oct 28 | 8 AM PST | 11 AM EST
๐ฅ Register Now โ https://thn.news/secure-stack-webinar
๐ฅ7
๐จ Static secrets are fading fast.
Teams using managed identities cut 95% of credential hassleโyet hidden API keys still lurk in legacy systems.
The fix? Run NHI discovery to find every key, then migrate 70โ80% to managed identities.
Your roadmap โ https://thehackernews.com/2025/10/why-organizations-are-abandoning-static.html
Teams using managed identities cut 95% of credential hassleโyet hidden API keys still lurk in legacy systems.
The fix? Run NHI discovery to find every key, then migrate 70โ80% to managed identities.
Your roadmap โ https://thehackernews.com/2025/10/why-organizations-are-abandoning-static.html
๐7
From crypto fines to malware & data leaks โ the weekโs biggest cyber hits:
๐จ๐ฆ Cryptomus fined $176M
๐ฐ๏ธ Starlink scam crackdown
๐ค AI vuln in Oat++ MCP
๐ง Tykit phishing campaign
.... 15+ more important news stories.
Read the latest #ThreatsDay Bulletin ๐ https://thehackernews.com/2025/10/threatsday-bulletin-176m-crypto-fine.html
๐จ๐ฆ Cryptomus fined $176M
๐ฐ๏ธ Starlink scam crackdown
๐ค AI vuln in Oat++ MCP
๐ง Tykit phishing campaign
.... 15+ more important news stories.
Read the latest #ThreatsDay Bulletin ๐ https://thehackernews.com/2025/10/threatsday-bulletin-176m-crypto-fine.html
โก9๐ฅ2
๐ข WEBINAR ALERT!
You canโt secure what you canโt see. AI agents are spreading fast โ unseen, unmanaged & risky.
Join this free #cybersecurity session to learn how leading security teams are regaining control & speed.
๐๏ธ 27 Oct, 2025
๐ Watch This โ https://thehackernews.com/2025/10/secure-ai-at-scale-and-speed-learn.html
You canโt secure what you canโt see. AI agents are spreading fast โ unseen, unmanaged & risky.
Join this free #cybersecurity session to learn how leading security teams are regaining control & speed.
๐๏ธ 27 Oct, 2025
๐ Watch This โ https://thehackernews.com/2025/10/secure-ai-at-scale-and-speed-learn.html
๐ฅ8
North Korean hackers are posing as recruitersโagain.
This time, theyโre stealing drone tech from Europeโs defense firms.
The trap? A fake job PDF hiding a remote access tool.
Itโs been activeโundetectedโsince March.
Read โ https://thehackernews.com/2025/10/north-korean-hackers-lure-defense.html
This time, theyโre stealing drone tech from Europeโs defense firms.
The trap? A fake job PDF hiding a remote access tool.
Itโs been activeโundetectedโsince March.
Read โ https://thehackernews.com/2025/10/north-korean-hackers-lure-defense.html
๐ค13๐ฑ6๐2
๐จ GlassWorm hits VS Code extensions โ 14 infected builds, ~35K installs since Oct 17 2025.
It steals dev creds, drains crypto wallets, turns machines into bots โ and auto-updates itself.
Read โ https://thehackernews.com/2025/10/self-spreading-glassworm-infects-vs.html
It steals dev creds, drains crypto wallets, turns machines into bots โ and auto-updates itself.
Read โ https://thehackernews.com/2025/10/self-spreading-glassworm-infects-vs.html
๐14๐2๐ฅ2